Improper Data Query Handling in Ash_SQLite Affects Sensitive Information Access
CVE-2026-77846

2.1LOW

Key Information:

Vendor
CVE Published:
30 August 2026

What is CVE-2026-77846?

The ash_sqlite component from the ash-project is prone to a vulnerability that permits attackers to exploit the get_path/2 function, leading to unauthorized traversal through nested JSON data structures. This flaw arises from inadequate handling of JSON paths, where specific input values such as ., [, ], or $ can misinterpret the intended traversal, allowing access to embedded fields initially meant to remain hidden. Any endpoint that permits user influence over the get_path segment could inadvertently expose sensitive or private information. This issue primarily affects ash_sqlite versions from 0.1.2-rc.0 and below 0.2.18.

Affected Version(s)

ash_sqlite 0.1.2-rc.0 < 0.2.18

ash_sqlite c12be48a5b6295593199b0e445b70a4aef81d1cd < 2138480fceb654bec1845e691517ac409d0232c3

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.